ExamGecko
Question list
Search
Search

Related questions

Question 409 - CISA discussion

Report
Export

During audit framework. an IS auditor teams that employees are allowed to connect their personal devices to company-owned computers. How can the auditor BEST validate that appropriate security controls are in place to prevent data loss?

A.
Conduct a walk-through to view results of an employee plugging in a device to transfer confidential data.
Answers
A.
Conduct a walk-through to view results of an employee plugging in a device to transfer confidential data.
B.
Review compliance with data loss and applicable mobile device user acceptance policies.
Answers
B.
Review compliance with data loss and applicable mobile device user acceptance policies.
C.
Verify the data loss prevention (DLP) tool is properly configured by the organization.
Answers
C.
Verify the data loss prevention (DLP) tool is properly configured by the organization.
D.
Verify employees have received appropriate mobile device security awareness training.
Answers
D.
Verify employees have received appropriate mobile device security awareness training.
Suggested answer: B

Explanation:

The best way to validate that appropriate security controls are in place to prevent data loss is to review compliance with data loss and applicable mobile device user acceptance policies. This will ensure that the organization has established clear rules and guidelines for employees to follow when connecting their personal devices to company-owned computers. A walk-through, a DLP tool configuration, and a security awareness training are not sufficient to validate the effectiveness of the controls, as they may not cover all possible scenarios and risks.Reference:IT Audit Fundamentals Certificate Resources

asked 18/09/2024
Aung Aung Myo Myint
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first